CVE-2026-65916
HIGHCyberPanel Missing Authorization in cancelBackupCreation Handler
Title source: cnaDescription
CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kill, delete, and corrupt other tenants' backups. Attackers can send crafted POST requests with arbitrary backupCancellationDomain and fileName parameters to terminate backup processes, delete backup archives, corrupt backup status files, and remove database records belonging to other tenants.
References (3)
Core 3
Core References
Patch patch
Patch Commit
https://github.com/usmannasir/cyberpanel/commit/b1984603f9b0099b39bca46fea176e53b6d4d601
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/cyberpanel-missing-authorization-in-cancelbackupcreation-handler
Exploit technical-description
exploit
issue-tracking
Researcher Disclosure
https://github.com/usmannasir/cyberpanel/issues/1829
Scores
CVSS v3
8.1
EPSS
0.0034
EPSS Percentile
26.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-862
Status
published
Products (2)
usmannasir/cyberpanel
< 1.9.1
usmannasir/cyberpanel
b1984603f9b0099b39bca46fea176e53b6d4d601
Published
Jul 23, 2026
Tracked Since
Jul 23, 2026